Live data from Hacker News

How to effectively evade the GDPR and the reach of the DPA

blog.zoller.lu

41–50 of 200 posts

Re: How to effectively evade the GDPR and the reach of the DPA

#41
In this particular case, GDPR can get enforced for the buyers of data.

Rocket Reach and similar companies may be outside the reach of GDPR, however, all the advertisers and global platforms who actually want to target EU customers are within the reach of GDPR so it's illegal for them to buy data from Rocket Reach.

Re: How to effectively evade the GDPR and the reach of the DPA

#43
post #11
post #2

"Rocketreach has not met the requirement of the GDPR to name an EU representative (Art27) to account for the processing of European Personal Data. In their answer, the CNPD makes it sound like it is optional, it isn't. Instead of pursuing Rocketreach locally on that basis alone" LOL, yes. I'm sure they also do not meet the legal requirements of North Korea, Saudi Arabia, and many others. Likewise, various EU corporat…

> I'm sure they also do not meet the legal requirements of North Korea, Saudi Arabia, and many others. China is the most straightforward example, companies cannot operate unless they basically do it through an - implicitly Chinese state controlled - partner company. China also has a literal Great Firewall monitoring, modifying or stopping all cross-border traffic. So yes, you have to play by their rules if you want a…

I think your information may be a bit out of date, in China you can own and operate as a WFOE

https://en.m.wikipedia.org/wiki/Wholly_foreign-owned_enterpr...

Re: How to effectively evade the GDPR and the reach of the DPA

#44

Earlier quoted context omitted.

> trading in USD requires the transaction to route via the US Is this correct? How's that enforced? Say, I have a company in Poland which sells some goods for a million dollars to another company in Poland. We both have USD accounts in Polish banks and the transfer is between these accounts. How does the money route via the US?

The bank will either have a presence in the US itself, or it'll have a partner that does that it'll route the transaction through. If you've done a USD transfer, it'll most likely be a SWIFT transfer, and you can ask your bank for the SWIFT routing log. You'll most likely see an NYC bank (or NYC branch of your bank) in the middle.

USD transfers even within same non-US based bank let's say same example in Poland is done with SWIFT, but unlikely it goes thru NYC bank as the cost is none and the transfer is instant. SWIFT is used only for addressing and accounting in such case.

Re: How to effectively evade the GDPR and the reach of the DPA

#45

I'm not sure how I feel about the screenshot at the end, showing that various policy makers also have their personal information being sold. I guess the information is out there, and doing so also makes it definitively personal for the policy makers / enforcers involved. That said, the policy makers / enforcers may be genuinely hamstrung. The US imposes its laws globally because of it's status as a global reserve cur…

> The EU doesn't have such status or power over US companies. The most it can do is try to prevent them from operating in the region.

Wouldn't that already be quite a step? I don't know who they're selling the data to, but it should at least be possible to prevent them from selling that data to organisations with a European presence, right?

Re: How to effectively evade the GDPR and the reach of the DPA

#46

Currently there's not much the data protection authorities in the EU can do about foreign companies abusing the data of users. I assume that in the coming years (or decade?) there will be more efforts to ensure the enforcement of EU law for foreign companies that offer services to EU citizens as part of trade deals. Right now there's e.g. a flourishing industry of data brokers in Israel that illegally collects data f…

It is enforced and viral in EU. Think of it like radioactive materials, any operation needs to be fully tracked.

While accessing any user personal details you need to have user consent to process their personal data. You can't simply buy the dataset and assume it has consent. When you buy data from data provider you need to make sure user gave consent to handle data by third-parties to that provider in accordance to GDPR. Users can revoke the consent, every party needs to be ready to handle that scenario. Any data export outside EU GDPR also needs consent. Moreover the dataset needs to be registered with local regulator.

Re: How to effectively evade the GDPR and the reach of the DPA

#47

I'm not sure how I feel about the screenshot at the end, showing that various policy makers also have their personal information being sold. I guess the information is out there, and doing so also makes it definitively personal for the policy makers / enforcers involved. That said, the policy makers / enforcers may be genuinely hamstrung. The US imposes its laws globally because of it's status as a global reserve cur…

> trading in USD requires the transaction to route via the US Is this correct? How's that enforced? Say, I have a company in Poland which sells some goods for a million dollars to another company in Poland. We both have USD accounts in Polish banks and the transfer is between these accounts. How does the money route via the US?

It's not enforced but it's a de facto practical requirement.

If Polbank (forgive me for the bastardized names) wants to give 1M USD to Bankpolska, they either need to ship cash (which can be done but is expensive or tricky) or have a specific bilateral agreement betwene them (which can be done and is done sometimes, but linking every bank with every other bank bilaterally does not scale), or need some interbank settlement system that will do that, but there's no such system in which they can participate. E.g. there's Fedwire but neither Polbank or Bankpolska can be direct members as far as I understand (they generally are not members; I'm not certain if it's caused by some strict limitation or just practicalities and costs.)

So the standard means is to use 'correspondent banks' e.g. USA banks that do that for them. Polbank might have an USD account with Chase or Citi, and Polbank can ask Chase (via a SWIFT message usually) "hey transfer $1m from our account to Bankpolska, it's cover for a customer deal #1234" - but this means that the transaction "goes through" USA.

Alternatively, multinational banks may have branches in both USA and Poland and so they can be direct participants and settle this directly, however, then it would involve a Fedwire transfer (in USA, subject to USA laws and limitations) between Polbank USA branch and Bankpolska USA branch.

That's standard practice for pretty much every currency. EUR settlement between two American banks usually (not always, there are various options) goes through EU, RUB settlement usually goes through Russia, etc.

If there's a sufficient need, Polish banks could establish an interbank settlement system through which they could transfer USD directly (e.g. similar to the one they have for transfering Polish zloty), but it's a hassle and has costs, so currently they have not done so because for them it's generally not a problem to route all USD payments through USA.

Re: How to effectively evade the GDPR and the reach of the DPA

#48
post #44

Earlier quoted context omitted.

The bank will either have a presence in the US itself, or it'll have a partner that does that it'll route the transaction through. If you've done a USD transfer, it'll most likely be a SWIFT transfer, and you can ask your bank for the SWIFT routing log. You'll most likely see an NYC bank (or NYC branch of your bank) in the middle.

USD transfers even within same non-US based bank let's say same example in Poland is done with SWIFT, but unlikely it goes thru NYC bank as the cost is none and the transfer is instant. SWIFT is used only for addressing and accounting in such case.

Within the same bank it's just internal accounting. But when two different banks are involved, an USD transfer generally goes through USA.

Re: How to effectively evade the GDPR and the reach of the DPA

#50

Earlier quoted context omitted.

> trading in USD requires the transaction to route via the US Is this correct? How's that enforced? Say, I have a company in Poland which sells some goods for a million dollars to another company in Poland. We both have USD accounts in Polish banks and the transfer is between these accounts. How does the money route via the US?

It's not enforced but it's a de facto practical requirement. If Polbank (forgive me for the bastardized names) wants to give 1M USD to Bankpolska, they either need to ship cash (which can be done but is expensive or tricky) or have a specific bilateral agreement betwene them (which can be done and is done sometimes, but linking every bank with every other bank bilaterally does not scale), or need some interbank settl…

Thanks for the explanation this makes more sense
Post reply on HN